zookeeper-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "ASF GitHub Bot (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (ZOOKEEPER-2906) The OWASP dependency check jar should not be included in the default classpath
Date Thu, 28 Sep 2017 22:06:00 GMT

    [ https://issues.apache.org/jira/browse/ZOOKEEPER-2906?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16184978#comment-16184978

ASF GitHub Bot commented on ZOOKEEPER-2906:

Github user afine commented on a diff in the pull request:

    --- Diff: build.xml ---
    @@ -121,6 +121,7 @@ xmlns:cs="antlib:com.puppycrawl.tools.checkstyle.ant">
         <property name="ivy.test.lib" value="${build.dir}/test/lib"/>
         <property name="ivy.jdiff.lib" value="${build.dir}/jdiff/lib"/>
         <property name="ivy.javacc.lib" value="${build.dir}/javacc/lib"/>
    +    <property name="ivy.owasp.lib" value="${build.dir}/owasp/lib"/>
    --- End diff --
    the reports are output to build/test/owasp/ in order to match what we do with clover
    so i felt it was best to follow convention rather than drop the actual report in with
the dependencies

> The OWASP dependency check jar should not be included in the default classpath
> ------------------------------------------------------------------------------
>                 Key: ZOOKEEPER-2906
>                 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-2906
>             Project: ZooKeeper
>          Issue Type: Bug
>    Affects Versions: 3.5.4, 3.6.0, 3.4.11
>            Reporter: Abraham Fine
>            Assignee: Abraham Fine
> The owasp dependency-check-ant jar that we use contains a SLF4J binding that can break
logging. We should move it into a separate classpath. 

This message was sent by Atlassian JIRA

View raw message